Privacy policy
Last updated: 18 June 2026
This Privacy Policy describes how Barrelhand Inc. ("Barrelhand," "we," "us," or "our") collects, uses, discloses, and protects your personal information when you use our website, online store, reservation system, and related services (the "Service"), and explains your privacy rights and how the law protects you.
By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy. This Privacy Policy should be read together with our Terms and Conditions and our Cookie Policy.
1. Controller and Contact
Barrelhand Inc. is the controller of personal data processed through the Service.
Barrelhand Inc. Delaware corporation (Delaware File Number 6562907)
Registered office: 651 N. Broad Street, Suite 206, Middletown, New Castle County, DE 19709, USA
Principal place of business: San Francisco, California, USA
Email: contact (at) barrelhand.com
For the purposes of the EU and UK General Data Protection Regulation (GDPR), Barrelhand is the Data Controller. For the purposes of the California Consumer Privacy Act and California Privacy Rights Act (together, "CCPA"), Barrelhand is the Business.
2. Definitions
Personal Data means any information that relates to an identified or identifiable individual.
Usage Data means data collected automatically through use of the Service or generated by the Service infrastructure, such as IP address, browser type, pages visited, and the date and duration of a visit.
Service Provider (also a Data Processor under the GDPR) means any third party that processes personal data on Barrelhand's behalf to help operate, provide, or analyze the Service.
Cookies are small files placed on your device that store information about your browsing activity. Our use of cookies is described in our Cookie Policy.
You means the individual using the Service. Under the GDPR you may also be referred to as the Data Subject.
3. Personal Data We Collect
We collect the following categories of personal data:
Information you provide directly. Name, email address, postal and shipping address, telephone number, order and reservation details, and communications you send to us.
Payment information. When you purchase a product, payment is processed by our payment provider. We do not store or collect your full payment card details; that information is provided directly to our payment processor (see Section 8).
Identity verification information. For certain transactions, including payments made by bank transfer or where verification is required for fraud, anti-money-laundering, or sanctions screening, we may ask for additional information such as date of birth or a government-issued identification document.
Source Files request information. When you request access to the Monolith Source Files, we collect your email address and your stated field of interest in order to provide the requested files and to administer access under the Barrelhand Research and Development License (BRDL). This information is used for access administration only and is not used for marketing.
Withdrawal and returns information. When you exercise a statutory right of withdrawal or request a return, we collect your name, order reference, and email address through our withdrawal form or by direct contact, in order to process and document your request as described in Section 6.
Usage Data. Collected automatically when you use the Service, as described in Section 2 and in our Cookie Policy.
4. How We Use Personal Data
We use personal data for the following purposes:
- To provide and operate the Service, including processing reservations, orders, payments, shipping, and returns.
- To perform our contract with you, including fulfilling purchases and administering reservations and pre-orders.
- To comply with legal obligations, including consumer protection, tax, customs, export control, sanctions, and recordkeeping requirements, and to process and document statutory withdrawal requests.
- To administer access to the Monolith Source Files under the BRDL.
- To communicate with you about your orders, reservations, requests, and service matters, including security and transactional notices.
- To send marketing communications where you have consented or where otherwise permitted by law. You may opt out of marketing at any time using the unsubscribe link in any marketing email or by contacting us. We do not add Source Files requesters to marketing lists.
- To protect the Service, detect and prevent fraud, and ensure security and compliance.
- To evaluate or conduct a business transfer, such as a merger, financing, restructuring, or sale of assets, in which personal data may be among the assets transferred.
5. Legal Bases for Processing (GDPR)
Where the GDPR applies, we rely on the following legal bases:
Performance of a contract, for processing necessary to fulfill your order, reservation, or other agreement with us, and to take steps at your request before entering into a contract.
Compliance with a legal obligation, for processing required by law, including statutory withdrawal and returns handling, tax, customs, export control, and sanctions compliance.
Legitimate interests, for operating and securing the Service, preventing fraud, administering access to the Monolith Source Files, and limited analytics, provided these interests are not overridden by your rights. Access to the Source Files is provided on the basis of our legitimate interest in distributing and administering the files under the BRDL.
Consent, for marketing communications where consent is required and for non-essential cookies. You may withdraw consent at any time, without affecting processing carried out before withdrawal.
6. Statutory Withdrawal and Returns
Where you exercise a statutory right of withdrawal under applicable consumer law, or request a voluntary return, we process the personal data you submit (name, order reference, and email address) in order to verify, process, and document your request, and to issue any reimbursement due.
Withdrawal requests submitted through our withdrawal form are processed using a third-party form provider acting as our Service Provider, and a copy of each request is sent to and retained by Barrelhand. We retain withdrawal and returns records for as long as necessary to evidence our compliance with applicable consumer protection law and to meet related legal, accounting, and recordkeeping obligations.
The legal basis for this processing is compliance with a legal obligation and performance of our contract with you.
7. How We Share Personal Data
We share personal data only as described below:
With Service Providers, including our website host, payment processor, email and analytics providers, and form providers, who process personal data on our behalf under contracts that require them to protect it and use it only for the services they provide to us.
For legal and compliance reasons, where disclosure is necessary to comply with law, respond to lawful requests by public authorities, enforce our agreements, or protect the rights, safety, or property of Barrelhand, our users, or others.
In a business transfer, in connection with a merger, financing, restructuring, acquisition, or sale of assets, subject to appropriate safeguards.
We do not sell your personal data, and we have not sold personal data in the preceding twelve months. We do not share personal data for cross-context behavioral advertising in exchange for valuable consideration.
8. Service Providers
The Service Providers we use may have access to personal data only as needed to perform their functions and in accordance with their own privacy policies.
- Website hosting: Webflow. Privacy policy: https://webflow.com/legal/privacy
- Payments: Shopify. We do not store full payment card details; payment data is handled by the processor in accordance with PCI-DSS. Privacy policy: https://www.shopify.com/legal/privacy
- Email and marketing: Mailchimp (The Rocket Science Group LLC). Privacy policy: https://mailchimp.com/legal/privacy/
- Analytics: Google Analytics. Privacy policy: https://policies.google.com/privacy. You can opt out using the Google Analytics opt-out browser add-on.
- Forms (including the withdrawal form): a third-party form provider used to receive and route form submissions to Barrelhand.
This list may change as our providers change; we will update this Privacy Policy accordingly.
9. International Data Transfers
Barrelhand is established in the United States, and personal data is processed in the United States and in other locations where our Service Providers operate. This means your personal data may be transferred to, and processed in, countries whose data protection laws differ from those of your country of residence.
Where we transfer personal data of individuals in the European Economic Area, the United Kingdom, or Switzerland to a country that has not been recognized as providing an adequate level of protection, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), or another lawful transfer mechanism. You may request information about the safeguards we apply by contacting us at the address in Section 1.
10. Data Retention
We retain personal data only for as long as necessary for the purposes described in this Privacy Policy, including to provide the Service, to comply with our legal, tax, accounting, and consumer protection obligations, to resolve disputes, and to enforce our agreements. Withdrawal and returns records are retained as described in Section 6. Usage Data is generally retained for a shorter period, except where a longer period is needed for security or to meet a legal obligation. When personal data is no longer required, we delete or anonymize it.
11. Data Security
We use commercially reasonable technical and organizational measures to protect personal data. However, no method of transmission over the Internet or method of electronic storage is fully secure, and we cannot guarantee absolute security.
12. Your Rights under the GDPR
If you are in the EEA or the UK, you have the right to access, correct, update, or delete your personal data; to restrict or object to processing; to data portability; and to withdraw consent where processing is based on consent. Where processing is based on our legitimate interests, you may object on grounds relating to your particular situation, and you may object to direct marketing at any time.
To exercise these rights, contact us at contact (at) barrelhand.com. We may ask you to verify your identity. You also have the right to lodge a complaint with your local supervisory authority. If you are in the EEA, you may contact your national data protection authority; if you are in the UK, you may contact the Information Commissioner's Office.
13. Your Rights under the CCPA (California Residents)
This section applies to California residents and supplements the rest of this Privacy Policy.
Categories of personal information collected. In the preceding twelve months we have collected the following CCPA categories: identifiers (such as name, email, postal address, and IP address); California Customer Records information (such as name, contact details, and payment-related information); commercial information (such as records of products purchased or considered); and Internet or other network activity (such as interactions with the Service). We do not collect biometric information, geolocation beyond approximate region inferred from IP address, protected classification characteristics, sensory data, professional or education information, or inferences used for profiling.
Sources. We collect personal information directly from you, automatically through your use of the Service, and from our Service Providers.
Purposes. We use personal information for the business purposes described in Section 4.
Disclosure. In the preceding twelve months we may have disclosed identifiers, California Customer Records information, commercial information, and network activity to Service Providers for business purposes, under contracts that restrict their use of the information.
No sale or sharing. We do not sell personal information and have not sold personal information in the preceding twelve months. We do not share personal information for cross-context behavioral advertising in exchange for valuable consideration.
Your California rights. You have the right to know what personal information we collect, use, and disclose; the right to request deletion, subject to legal exceptions; the right to correct inaccurate personal information; and the right not to be discriminated against for exercising your rights. Because we do not sell or share personal information as defined by the CCPA, no opt-out of sale or sharing is required, though you may still submit a request to confirm this.
To exercise these rights, contact us at contact (at) barrelhand.com. We will verify your request and respond within the time periods required by law. You may use an authorized agent to submit a request on your behalf.
14. Cookies and Tracking
We use cookies and similar technologies as described in our Cookie Policy. You can control cookies through your browser settings; disabling some cookies may affect the functionality of the Service. Our Service does not respond to "Do Not Track" browser signals.
15. Children's Privacy
The Service is intended for adults and is not directed to minors. We do not knowingly collect personal data from anyone under the age of 18. If you believe a minor has provided us with personal data, please contact us and we will take steps to delete it. This includes compliance with the Children's Online Privacy Protection Act (COPPA) for children under 13 and with applicable minimum-age requirements under the GDPR and CCPA.
16. Links to Other Websites
The Service may contain links to websites not operated by Barrelhand. We are not responsible for the content or privacy practices of those sites, and we encourage you to review their privacy policies.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will post the updated version on this page with a new "Last updated" date and, where appropriate, provide additional notice. Changes are effective when posted.
18. Contact Us
For questions about this Privacy Policy or to exercise your rights, contact:
Barrelhand Inc.
Email: contact (at) barrelhand.com